Vulnerability Name: | CVE-2001-0559 (CCN-6508) | ||||||||
Assigned: | 2001-05-07 | ||||||||
Published: | 2001-05-07 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon May 07 2001 - 17:08:49 CDT Vixie cron vulnerability Source: CCN Type: BugTraq Mailing List, Tue May 08 2001 - 16:01:21 CDT Re: Vixie cron vulnerability Source: CCN Type: BugTraq Mailing List, Tue May 08 2001 - 10:30:55 CDT Re: Vixie cron vulnerability Source: MITRE Type: CNA CVE-2001-0559 Source: CCN Type: Conectiva Linux Announcement CLSA-2003:628 vixie-cron Source: CCN Type: Conectiva Linux Announcement CLSA-2003:758 vixie-cron Source: DEBIAN Type: Vendor Advisory DSA-054 Source: DEBIAN Type: DSA-054 cron -- local root exploit Source: MANDRAKE Type: Patch, Vendor Advisory MDKSA-2001:050 Source: SUSE Type: UNKNOWN SuSE-SA:2001:17 Source: CCN Type: OSVDB ID: 1813 Vixie Cron crontab Privilege Lowering Failure Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20010507 Vixie cron vulnerability Source: BID Type: Exploit, Patch, Vendor Advisory 2687 Source: CCN Type: BID-2687 Vixie Cron crontab Privilege Lowering Failure Vulnerability Source: CCN Type: BID-8759 Conectiva Vixie-Cron Package Potential Denial Of Service Vulnerability Source: CCN Type: SuSE Security Announcement SuSE-SA:2001:017 cron-3.0.1-296 Source: XF Type: UNKNOWN vixie-cron-gain-privileges(6508) Source: XF Type: UNKNOWN vixie-cron-gain-privileges(6508) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |